Repository navigation
bound trim margin to avoid signed overflow in extract size - #4552
Merged
Merged
Conversation
Owner
|
Thank you |
dadezzz
pushed a commit
to dadezzz/university_notes
that referenced
this pull request
Jul 5, 2026
This PR contains the following updates: | Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) | |---|---|---|---| | [sharp](https://sharp.pixelplumbing.com) ([source](https://github.com/lovell/sharp), [changelog](https://github.com/lovell/sharp/blob/main/docs/src/content/docs/changelog.md)) | [`0.35.2` → `0.35.3`](https://renovatebot.com/diffs/npm/sharp/0.35.2/0.35.3) |  |  | --- ### Release Notes <details> <summary>lovell/sharp (sharp)</summary> ### [`v0.35.3`](https://github.com/lovell/sharp/releases/tag/v0.35.3) [Compare Source](lovell/sharp@v0.35.2...v0.35.3) - Tighten verification of `text` dimensions, TIFF tile dimensions and `extend` values. - Improve code bundler support by resolving path to libvips binary. - Increase default concurrency when use of `MALLOC_ARENA_MAX` is detected. - Emit warning about binaries provided by Electron for use on Linux. - Add `hasAlpha` property to output `info`. [#​4500](lovell/sharp#4500) - TypeScript: Return more precise `Buffer<ArrayBuffer>` from `toBuffer`. [#​4520](lovell/sharp#4520) [@​Andarist](https://github.com/Andarist) - Bound `clahe` width and height to avoid signed overflow. [#​4551](lovell/sharp#4551) [@​metsw24-max](https://github.com/metsw24-max) - Bound `trim` margin to avoid signed overflow. [#​4552](lovell/sharp#4552) [@​metsw24-max](https://github.com/metsw24-max) - Reject infinite values when validating numbers. [#​4553](lovell/sharp#4553) [@​metsw24-max](https://github.com/metsw24-max) - Bound extract region to libvips coordinate limit. [#​4555](lovell/sharp#4555) [@​metsw24-max](https://github.com/metsw24-max) - Verify background colour values are numbers. [#​4556](lovell/sharp#4556) [@​metsw24-max](https://github.com/metsw24-max) - Bound create and raw input dimensions to coordinate limit. [#​4558](lovell/sharp#4558) [@​metsw24-max](https://github.com/metsw24-max) - Tighten recomb and affine matrix verification. [#​4560](lovell/sharp#4560) [@​chatman-media](https://github.com/chatman-media) - Verify cache memory limit to avoid overflow. [#​4561](lovell/sharp#4561) [@​metsw24-max](https://github.com/metsw24-max) </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Mend Renovate](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yNDYuMSIsInVwZGF0ZWRJblZlciI6IjQzLjI0Ni4xIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6W119-->
paultibbetts
added a commit
to paultibbetts/dev
that referenced
this pull request
Jul 7, 2026
This PR contains the following updates: | Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) | |---|---|---|---| | [@astrojs/starlight](https://starlight.astro.build) ([source](https://github.com/withastro/starlight/tree/HEAD/packages/starlight)) | [`^0.40.0` → `^0.41.0`](https://renovatebot.com/diffs/npm/@astrojs%2fstarlight/0.40.0/0.41.3) |  |  | | [sharp](https://sharp.pixelplumbing.com) ([source](https://github.com/lovell/sharp), [changelog](https://github.com/lovell/sharp/blob/main/docs/src/content/docs/changelog.md)) | [`0.35.2` → `0.35.3`](https://renovatebot.com/diffs/npm/sharp/0.35.2/0.35.3) |  |  | --- ### Release Notes <details> <summary>withastro/starlight (@​astrojs/starlight)</summary> ### [`v0.41.3`](https://github.com/withastro/starlight/blob/HEAD/packages/starlight/CHANGELOG.md#0413) [Compare Source](https://github.com/withastro/starlight/compare/@astrojs/[email protected]...@astrojs/[email protected]) ##### Patch Changes - [#​3911](withastro/starlight#3911) [`1686ecc`](withastro/starlight@1686ecc) Thanks [@​timothyjordan](https://github.com/timothyjordan)! - Keeps keyboard focus inside the mobile menu while it is open, preventing focus moving to hidden interactive elements in page content. ### [`v0.41.2`](https://github.com/withastro/starlight/blob/HEAD/packages/starlight/CHANGELOG.md#0412) [Compare Source](https://github.com/withastro/starlight/compare/@astrojs/[email protected]...@astrojs/[email protected]) ##### Patch Changes - [#​4008](withastro/starlight#4008) [`58a3520`](withastro/starlight@58a3520) Thanks [@​FrancoKaddour](https://github.com/FrancoKaddour)! - Fixes the table of contents overflowing the right edge of the viewport when a custom `--sl-content-width` value exceeds available space - [#​4015](withastro/starlight#4015) [`bdbfffc`](withastro/starlight@bdbfffc) Thanks [@​delucis](https://github.com/delucis)! - Fixes an issue where aside icons were rendered incorrectly in projects where Astro’s MDX integration had optimization disabled ### [`v0.41.1`](https://github.com/withastro/starlight/blob/HEAD/packages/starlight/CHANGELOG.md#0411) [Compare Source](https://github.com/withastro/starlight/compare/@astrojs/[email protected]...@astrojs/[email protected]) ##### Patch Changes - [#​3967](withastro/starlight#3967) [`72e63dc`](withastro/starlight@72e63dc) Thanks [@​HiDeoo](https://github.com/HiDeoo)! - Adds 2 new icons: `link` and `link-alt`. - [#​3988](withastro/starlight#3988) [`ac55cfa`](withastro/starlight@ac55cfa) Thanks [@​delucis](https://github.com/delucis)! - Fixes a dependency resolution issue introduced in Starlight v0.41 - [#​3967](withastro/starlight#3967) [`72e63dc`](withastro/starlight@72e63dc) Thanks [@​HiDeoo](https://github.com/HiDeoo)! - Optimizes the icons of Markdown asides. ### [`v0.41.0`](https://github.com/withastro/starlight/blob/HEAD/packages/starlight/CHANGELOG.md#0410) [Compare Source](https://github.com/withastro/starlight/compare/@astrojs/[email protected]...@astrojs/[email protected]) ##### Minor Changes - [#​3951](withastro/starlight#3951) [`1202dd4`](withastro/starlight@1202dd4) Thanks [@​HiDeoo](https://github.com/HiDeoo)! - Adds support for Astro v7, drops support for Astro v6. ##### Upgrade Astro and dependencies⚠️ **BREAKING CHANGE:** Astro v6 is no longer supported. Make sure you [update Astro](https://docs.astro.build/en/guides/upgrade-to/v7/) and any other official integrations at the same time as updating Starlight: ```sh npx @​astrojs/upgrade ``` *Community Starlight plugins and Astro integrations may also need to be manually updated to work with Astro v7. If you encounter any issues, please reach out to the plugin or integration author to see if it is a known issue or if an updated version is being worked on.*⚠️ **BREAKING CHANGE:** This release drops official support for Chromium-based browsers prior to version 111 (released 07 March 2023) and Safari-based browsers prior to version 16.4 (released 27 March 2023). You can find a list of currently supported browsers and their versions using this [browserslist query](https://browsersl.ist/#q=%3E+0.5%25%2C+not+dead%2C+Chrome+%3E%3D+111%2C+Edge+%3E%3D+111%2C+Firefox+%3E%3D+121%2C+Safari+%3E%3D+16.4%2C+iOS+%3E%3D+16.4%2C+not+op_mini+all). ##### Patch Changes - [#​3953](withastro/starlight#3953) [`a935d33`](withastro/starlight@a935d33) Thanks [@​HiDeoo](https://github.com/HiDeoo)! - Fixes Starlight Markdown processing being potentially applied to files that should not be processed. </details> <details> <summary>lovell/sharp (sharp)</summary> ### [`v0.35.3`](https://github.com/lovell/sharp/releases/tag/v0.35.3) [Compare Source](lovell/sharp@v0.35.2...v0.35.3) - Tighten verification of `text` dimensions, TIFF tile dimensions and `extend` values. - Improve code bundler support by resolving path to libvips binary. - Increase default concurrency when use of `MALLOC_ARENA_MAX` is detected. - Emit warning about binaries provided by Electron for use on Linux. - Add `hasAlpha` property to output `info`. [#​4500](lovell/sharp#4500) - TypeScript: Return more precise `Buffer<ArrayBuffer>` from `toBuffer`. [#​4520](lovell/sharp#4520) [@​Andarist](https://github.com/Andarist) - Bound `clahe` width and height to avoid signed overflow. [#​4551](lovell/sharp#4551) [@​metsw24-max](https://github.com/metsw24-max) - Bound `trim` margin to avoid signed overflow. [#​4552](lovell/sharp#4552) [@​metsw24-max](https://github.com/metsw24-max) - Reject infinite values when validating numbers. [#​4553](lovell/sharp#4553) [@​metsw24-max](https://github.com/metsw24-max) - Bound extract region to libvips coordinate limit. [#​4555](lovell/sharp#4555) [@​metsw24-max](https://github.com/metsw24-max) - Verify background colour values are numbers. [#​4556](lovell/sharp#4556) [@​metsw24-max](https://github.com/metsw24-max) - Bound create and raw input dimensions to coordinate limit. [#​4558](lovell/sharp#4558) [@​metsw24-max](https://github.com/metsw24-max) - Tighten recomb and affine matrix verification. [#​4560](lovell/sharp#4560) [@​chatman-media](https://github.com/chatman-media) - Verify cache memory limit to avoid overflow. [#​4561](lovell/sharp#4561) [@​metsw24-max](https://github.com/metsw24-max) </details> --- ### Configuration 📅 **Schedule**: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined). 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 👻 **Immortal**: This PR will be recreated if closed unmerged. Get [config help](https://github.com/renovatebot/renovate/discussions) if that's undesired. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Renovate Bot](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My44Mi4wIiwidXBkYXRlZEluVmVyIjoiNDMuODIuMCIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOlsiZGVwZW5kZW5jaWVzIl19--> --------- Co-authored-by: Paul Tibbetts <[email protected]> Reviewed-on: https://gitea.cloud.paultibbetts.uk/paul/dev/pulls/139 Co-authored-by: Renovate Bot <[email protected]> Co-committed-by: Renovate Bot <[email protected]>
suparious
pushed a commit
to SolidRusT/solidrust-ai-docs.github.io
that referenced
this pull request
Oct 3, 2026
This PR contains the following updates: | Package | Type | Update | Change | |---|---|---|---| | [sharp](https://sharp.pixelplumbing.com) ([source](https://github.com/lovell/sharp), [changelog](https://github.com/lovell/sharp/blob/main/docs/src/content/docs/changelog.md)) | dependencies | minor | [`^0.33.5` → `^0.35.5`](https://renovatebot.com/diffs/npm/sharp/0.33.5/0.35.5) | --- ### Release Notes <details> <summary>lovell/sharp (sharp)</summary> ### [`v0.35.5`](https://github.com/lovell/sharp/releases/tag/v0.35.5) [Compare Source](lovell/sharp@v0.35.4...v0.35.5) <https://github.com/lovell/sharp-libvips/releases/tag/v1.3.4> - Add upper bounds check on length of `linear` and GIF `delay` arrays. - Improve error handing when WebAssembly fallback also fails. [#​4593](lovell/sharp#4593) [@​lazerg](https://github.com/lazerg) - TypeScript: Allow multi-frame options for JXL output. [#​4602](lovell/sharp#4602) [@​ramin-010](https://github.com/ramin-010) - TypeScript: Remove non-existent named export. [#​4604](lovell/sharp#4604) - Increase accepted dimensions when extending an image. [#​4605](lovell/sharp#4605) - Improve gain map support for `extract` and `rotate` operations. [#​4606](lovell/sharp#4606) - Tests: Ensure composite tests pass on big endian platforms. [#​4609](lovell/sharp#4609) ### [`v0.35.4`](https://github.com/lovell/sharp/releases/tag/v0.35.4) [Compare Source](lovell/sharp@v0.35.3...v0.35.4) <https://github.com/lovell/sharp-libvips/releases/tag/v1.3.3> - Bound resize dimensions to coordinate limit. - Bound composite left and top to coordinate limit. [#​4564](lovell/sharp#4564) [@​metsw24-max](https://github.com/metsw24-max) - Round palette bit depth up for png and gif colours. [#​4569](lovell/sharp#4569) [@​metsw24-max](https://github.com/metsw24-max) - Ensure tiff.subifd input option is used. [#​4572](lovell/sharp#4572) [@​metsw24-max](https://github.com/metsw24-max) - Ensure `info.pages` is correct when limiting input page range. [#​4578](lovell/sharp#4578) [@​metsw24-max](https://github.com/metsw24-max) - Improve support for input Streams finishing before output is requested. [#​4584](lovell/sharp#4584) [@​Jaybhade](https://github.com/Jaybhade) ### [`v0.35.3`](https://github.com/lovell/sharp/releases/tag/v0.35.3) [Compare Source](lovell/sharp@v0.35.2...v0.35.3) - Tighten verification of `text` dimensions, TIFF tile dimensions and `extend` values. - Improve code bundler support by resolving path to libvips binary. - Increase default concurrency when use of `MALLOC_ARENA_MAX` is detected. - Emit warning about binaries provided by Electron for use on Linux. - Add `hasAlpha` property to output `info`. [#​4500](lovell/sharp#4500) - TypeScript: Return more precise `Buffer<ArrayBuffer>` from `toBuffer`. [#​4520](lovell/sharp#4520) [@​Andarist](https://github.com/Andarist) - Bound `clahe` width and height to avoid signed overflow. [#​4551](lovell/sharp#4551) [@​metsw24-max](https://github.com/metsw24-max) - Bound `trim` margin to avoid signed overflow. [#​4552](lovell/sharp#4552) [@​metsw24-max](https://github.com/metsw24-max) - Reject infinite values when validating numbers. [#​4553](lovell/sharp#4553) [@​metsw24-max](https://github.com/metsw24-max) - Bound extract region to libvips coordinate limit. [#​4555](lovell/sharp#4555) [@​metsw24-max](https://github.com/metsw24-max) - Verify background colour values are numbers. [#​4556](lovell/sharp#4556) [@​metsw24-max](https://github.com/metsw24-max) - Bound create and raw input dimensions to coordinate limit. [#​4558](lovell/sharp#4558) [@​metsw24-max](https://github.com/metsw24-max) - Tighten recomb and affine matrix verification. [#​4560](lovell/sharp#4560) [@​chatman-media](https://github.com/chatman-media) - Verify cache memory limit to avoid overflow. [#​4561](lovell/sharp#4561) [@​metsw24-max](https://github.com/metsw24-max) ### [`v0.35.2`](https://github.com/lovell/sharp/releases/tag/v0.35.2) [Compare Source](lovell/sharp@v0.35.1...v0.35.2) - TypeScript: Add `mediaType` to metadata response. [#​4492](lovell/sharp#4492) - Improve WebAssembly fallback detection. [#​4513](lovell/sharp#4513) - Improve code bundler support with stub binaries. [#​4543](lovell/sharp#4543) - Verify GIF `effort` option is an integer. [#​4544](lovell/sharp#4544) [@​metsw24-max](https://github.com/metsw24-max) - Verify `recomb` matrix entries are numbers. [#​4545](lovell/sharp#4545) [@​metsw24-max](https://github.com/metsw24-max) - TypeScript: Replace namespace with named exports for ESM. [#​4546](lovell/sharp#4546) - Bound dilate and erode width to avoid mask-size overflow. [#​4548](lovell/sharp#4548) [@​metsw24-max](https://github.com/metsw24-max) - Verify `convolve` kernel values are numbers. [#​4549](lovell/sharp#4549) [@​metsw24-max](https://github.com/metsw24-max) ### [`v0.35.1`](https://github.com/lovell/sharp/releases/tag/v0.35.1) [Compare Source](lovell/sharp@v0.35.0...v0.35.1) - TypeScript: Ensure type definitions are published for both ESM and CJS. [#​4537](lovell/sharp#4537) - WebAssembly: Ensure wrapper file is published. [#​4538](lovell/sharp#4538) ### [`v0.35.0`](https://github.com/lovell/sharp/releases/tag/v0.35.0) [Compare Source](lovell/sharp@v0.34.5...v0.35.0) - Breaking: Drop support for Node.js 18, now requires Node.js >= 20.9.0. - Breaking: Remove `install` script from `package.json` file. Compiling from source is now opt-in via the `build` script. - Breaking: Lossy AVIF output is now tuned using SSIMULACRA2-based `iq` quality metrics. - Breaking: Add `limitInputChannels` with a default value of 5. - Breaking: Remove deprecated `failOnError` constructor property. - Breaking: Remove deprecated `paletteBitDepth` from `metadata` response. - Breaking: Remove deprecated properties from `sharpen` operation. - Breaking: Rename `format.jp2k` as `format.jp2` for API consistency. - Upgrade to libvips v8.18.3 for upstream bug fixes. - Remove experimental status from WebAssembly binaries. - Add prebuilt binaries for FreeBSD (WebAssembly). - Deprecate Windows 32-bit (win32-ia32) prebuilt binaries. - Ensure TIFF output `bitdepth` option is limited to 1, 2 or 4. - Add AVIF/HEIF `tune` option for control over quality metrics. [#​4227](lovell/sharp#4227) - Add `keepGainMap` and `withGainMap` to process HDR JPEG images with embedded gain maps. [#​4314](lovell/sharp#4314) - Add `toUint8Array` for output image as a `TypedArray` backed by a transferable `ArrayBuffer`. [#​4355](lovell/sharp#4355) - Require prebuilt binaries using static paths to aid code bundling. [#​4380](lovell/sharp#4380) - TypeScript: Ensure `FormatEnum` keys match reality. [#​4475](lovell/sharp#4475) - Add `margin` option to `trim` operation. [#​4480](lovell/sharp#4480) [@​eddienubes](https://github.com/eddienubes) - Ensure HEIF primary item is used as default page/frame. [#​4487](lovell/sharp#4487) - Add image Media Type (MIME Type) to metadata response. [#​4492](lovell/sharp#4492) - Add `withDensity` to set output density in EXIF metadata. [#​4496](lovell/sharp#4496) - Improve `pkg-config` path discovery. [#​4504](lovell/sharp#4504) - Add WebP `exact` option for control over transparent pixel colour values. - Add support for ECMAScript Modules (ESM). [#​4509](lovell/sharp#4509) [@​florian-lefebvre](https://github.com/florian-lefebvre) ### [`v0.34.5`](https://github.com/lovell/sharp/releases/tag/v0.34.5) [Compare Source](lovell/sharp@v0.34.4...v0.34.5) - Upgrade to libvips v8.17.3 for upstream bug fixes. - Add experimental support for prebuilt Linux RISC-V 64-bit binaries. - Support building from source with npm v12+, deprecate `--build-from-source` flag. [#​4458](lovell/sharp#4458) - Add support for BigTIFF output. [#​4459](lovell/sharp#4459) [@​throwbi](https://github.com/throwbi) - Improve error messaging when only warnings issued. [#​4465](lovell/sharp#4465) - Simplify ICC processing when retaining input profiles. [#​4468](lovell/sharp#4468) ### [`v0.34.4`](https://github.com/lovell/sharp/releases/tag/v0.34.4) [Compare Source](lovell/sharp@v0.34.3...v0.34.4) - Upgrade to libvips v8.17.2 for upstream bug fixes. - Ensure TIFF `subifd` and OpenSlide `level` input options are respected (regression in 0.34.3). - Ensure `autoOrient` occurs before non-90 angle rotation. [#​4425](lovell/sharp#4425) - Ensure `autoOrient` removes existing metadata after shrink-on-load. [#​4431](lovell/sharp#4431) - TypeScript: Ensure `KernelEnum` includes `linear`. [#​4441](lovell/sharp#4441) [@​BayanBennett](https://github.com/BayanBennett) - Ensure `unlimited` flag is passed upstream when reading TIFF images. [#​4446](lovell/sharp#4446) - Support Electron memory cage when reading XMP metadata (regression in 0.34.3). [#​4451](lovell/sharp#4451) - Add sharp-libvips rpath for yarn v5 support. [#​4452](lovell/sharp#4452) [@​arcanis](https://github.com/arcanis) ### [`v0.34.3`](lovell/sharp@v0.34.2...v0.34.3) [Compare Source](lovell/sharp@v0.34.2...v0.34.3) ### [`v0.34.2`](lovell/sharp@v0.34.1...v0.34.2) [Compare Source](lovell/sharp@v0.34.1...v0.34.2) ### [`v0.34.1`](lovell/sharp@v0.34.0...v0.34.1) [Compare Source](lovell/sharp@v0.34.0...v0.34.1) ### [`v0.34.0`](lovell/sharp@v0.33.5...v0.34.0) [Compare Source](lovell/sharp@v0.33.5...v0.34.0) </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [x] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xMzIuMiIsInVwZGF0ZWRJblZlciI6IjQ0LjEzMi4yIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJkZXBlbmRlbmNpZXMiXX0=--> --------- Co-authored-by: Renovate Bot <[email protected]> Reviewed-on: https://gitea.hq.solidrust.net:30008/solidrust/solidrust-ai-docs.github.io/pulls/9 Co-authored-by: renovate-bot <[email protected]> Co-committed-by: renovate-bot <[email protected]>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Unbounded trim margin overflows the extract size
The
marginoption is only checked withis.integerand>= 0, so it lacks the upper bound the sibling pixel dimensions now carry. It is read viaAttrAsUint32and used inTrim()aswidth + 2 * margin, so a margin around 2^30 overflows the signed int into a negative extract width (a GLib-GObject-CRITICAL plus anextract_areafailure), while a margin around 2^31 narrows to a negative int and the nativemargin > 0guard then silently drops it. I have bounded it to 0..10000000 (VIPS_MAX_COORD), which keeps the existing 9999999 clamp test green and should make the limit easier to reason about alongside the other dimensions.